Hacker News new | ask | show | jobs
by hnlmorg 70 days ago
That’s just the docker daemon. The actual docker services would (or at least should) still be running as its own user/group just like they would if you were running them on the host.

And that’s exactly how any reputable image would be built.